HomeFrameworksNational Cyber & Cloud SchemesISMAP

Framework  National Cyber & Cloud Schemes

ISMAP

ISMAP (Information system Security Management and Assessment Program) is the Japanese government's scheme for evaluating and registering cloud services that meet its security requirements so that ministries and agencies can procure them without repeating the assessment.

It was announced in May 2020 and is run jointly by the National center of Incident readiness and Strategy for Cybersecurity (NISC), the Digital Agency, the Ministry of Internal Affairs and Communications, and the Ministry of Economy, Trade and Industry, with the Information-technology Promotion Agency (IPA) operating the program.

The control set (the ISMAP management standards) is built on JIS Q 27001, 27002, and 27017 with government-specific additions. A cloud provider implements the controls, has them examined by an audit firm registered on the ISMAP assessor list, and applies for registration; the ISMAP Steering Committee reviews the application and lists the service in the ISMAP Cloud Service List.

ISMAP-LIU (for Low-Impact Use), introduced in 2022, is a lighter track for SaaS used in low-risk government work.

In writing, a provider needs a management system aligned to the ISMAP standards, a control matrix with implementation statements for every applicable control, the system description and service scope, evidence of operating effectiveness for the audit period, the registered assessor's report, and the application package. Registration is renewed annually with a fresh assessment.

AI-compiled
Share
Sponsored
ISMAP
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with ISMAP
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Cloud service providers, Japanese or foreign, that want to sell to Japanese central government bodies, which are required to procure registered services in principle. Local governments and regulated industries increasingly reference the list as well.

What the assessor asks to see

Service scope and system description; ISMAP management standards control matrix with implementation statements; information security policy set; risk assessment; access management, cryptography, logging, change and vulnerability management, and incident handling evidence for the audit period; subcontractor and supply chain controls; data location information; business continuity tests; internal audit and management review; the registered assessor's report; prior registration records.

ISMAP-LIU

ISMAP for Low-Impact Use, launched in 2022, is a streamlined track for SaaS handling government information of lower sensitivity, with a narrower control set and lighter documentation while keeping an independent assessment and annual renewal.

Assessors

Who assesses ISMAP

Audit firms registered on the ISMAP assessor list maintained by IPA (in practice the large Japanese audit firms and affiliates of international networks). Registration decisions are made by the ISMAP Steering Committee. Accredited by IPA (as ISMAP operator) registers assessors; assessors are typically CPA-regulated audit firms operating under Japanese assurance standards.

Public register of assessors: https://www.ismap.go.jp/csm

No firm has claimed a ISMAP assessor listing yet. Claim yours →

Consultants

Who helps with ISMAP

Japanese consultancies and the advisory arms of audit firms help providers map controls, translate documentation, and prepare for the assessment; global providers often use a Japan-based partner. Readiness typically takes six to twelve months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a ISMAP consultant listing yet. Claim yours →

Software

Tools for ISMAP

Tools that name this framework in their own material.

No firm has claimed a ISMAP tool listing yet. Claim yours →

Related reading

  1. Information System Security Management and Assessment Program (ISMAP)Assessor's view of the registration path, the approved-assessor requirement and the improvement plan expected after findings.EY Japan
  2. ISMAP complianceDescribes what registration means for a cloud service and how Japanese government buyers use the ISMAP cloud service list.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISMAP

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with ISMAP

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.